KB5120714: Overview with user sentiment and feedback
Last Updated September 5, 2026
Probability of successful installation and continued operation of the machine
Overview
KB5120714 is the August 11, 2026 cumulative update for .NET Framework 3.5 and 4.8.1 on Windows Server 2022. This security-focused release addresses multiple critical vulnerabilities including elevation of privilege and remote code execution flaws. The update is recommended as part of standard maintenance routines and applies to systems running .NET Framework 3.5 or 4.8.1.
General Purpose
- Addresses six security vulnerabilities including CVE-2026-65810, CVE-2026-62872 (elevation of privilege), CVE-2026-62886, CVE-2026-62897, CVE-2026-70354 (remote code execution), and CVE-2026-62902 (information disclosure)
- Implements enhanced security protections for font handling and XPS package boundary restrictions in WPF applications
- Provides cumulative reliability improvements for .NET Framework components on Windows Server 2022
- Requires system restart and recommends closing .NET Framework-based applications before installation
General Sentiment
This update addresses significant security concerns with multiple critical vulnerabilities, making it a priority installation from a security perspective. However, the update introduces two confirmed compatibility issues affecting WPF applications that handle fonts and XPS documents, which may cause FileFormatException errors in production environments. Microsoft acknowledges these issues are under investigation and provides temporary workarounds, though these workarounds disable the new security protections.
Known Issues
- WPF applications may fail with System.IO.FileFormatException when printing or generating PDF/XPS content using certain fonts (including Calibri). Workaround available via AppContext switch but disables security protections.
- WPF applications printing or displaying print preview from in-memory XPS documents registered with System.IO.Packaging.PackageStore may fail with System.IO.FileFormatException. Workaround requires code rebuild or AppContext switch that disables security protections.
Disclaimer: We take measures to ensure that AI-generated content is of the highest possible quality, but we cannot guarantee its accuracy and recommend that users do their own independent research. Generated on 2026-09-05 01:08 AM